UBUNTU-CVE-2018-1000026
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1000026
UBUNTU-CVE-2018-1000026
Summary:
Details: Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
References: https://ubuntu.com/security/CVE-2018-1000026, https://patchwork.ozlabs.org/patch/859410/, http://lists.openwall.net/netdev/2018/01/16/40, http://lists.openwall.net/netdev/2018/01/18/96, https://git.kernel.org/linus/8914a595110a6eca69a5e275b323f5d09e18f4f9, https://git.kernel.org/linus/2b16f048729bf35e6c28a40cbfad07239f9dcd90, https://ubuntu.com/security/notices/USN-3617-1, https://ubuntu.com/security/notices/USN-3617-2, https://ubuntu.com/security/notices/USN-3617-3, https://ubuntu.com/security/notices/USN-3619-1, https://ubuntu.com/security/notices/USN-3620-1, https://ubuntu.com/security/notices/USN-3620-2, https://ubuntu.com/security/notices/USN-3619-2, https://ubuntu.com/security/notices/USN-3632-1, https://www.cve.org/CVERecord?id=CVE-2018-1000026
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
